Microsoft 365: why OneDrive and SharePoint are not a backup

Recycle bins, versions and retention reduce risk but have finite windows. Build a tested Microsoft 365 backup and restore strategy.

01

Service resiliency and backup address different risks

OneDrive and SharePoint are resilient collaboration platforms. Microsoft replicates data, protects the infrastructure and provides useful recovery tools. This lowers the risk of hardware failure or a recent deletion, but it does not automatically guarantee the organization's required retention, an independent recovery point or a measured recovery time for every critical site.

Saying 'Microsoft 365 has no backup' would be inaccurate: Microsoft now offers Microsoft 365 Backup as a separate service, alongside version history, recycle bins and retention policies. The real question is whether the capabilities included with OneDrive and SharePoint satisfy your loss scenarios, RPO, RTO, retention period and administrative-separation requirements. In many organizations, the answer is no without an additional backup policy.

Recovery windows and features vary by licence, tenant configuration and service changes. Validate them in your own environment before placing them in a continuity plan.

02

What the native protections actually recover

Native mechanisms are an excellent first line of defence. They are fast, integrated and often available to content owners. They are not interchangeable: the recycle bin restores a deleted item, version history rolls back a file, library restore reverses recent operations and Purview retention preserves content according to a lifecycle requirement.

MechanismDocumented window or scopeStrengthLimitation to plan for
Version historyTenant, site or library limitsFast recovery of a modified fileVersions can expire or be trimmed by policy
SharePoint recycle bins93 days total across both stagesDeleted files, lists, libraries or sitesSelf-service recovery ends after expiry or purge
Restore OneDriveFile and folder actions within the last 30 daysBroad rollback after deletion, corruption or ransomwareFiles purged from the recycle bin cannot be recovered by this feature
Restore a libraryActions within the last 30 daysBulk rollback for a modern libraryRelies on versions and recycle bin; does not restore an entirely deleted library
Purview retentionPolicy-defined durationPreservation, disposition and regulatory needsNot an operational restore workflow optimized for every incident
Microsoft 365 BackupSeparate policy from 3 months to 2 yearsRecovery points with granular or full restoreConsumption service that must be configured, monitored and tested
03

Version history is a collaboration feature, not an independent copy

Version history is valuable after an accidental edit or overwrite. Microsoft lets administrators set limits at the organization, site, library and OneDrive levels. The documented default for new libraries remains a manual limit of 500 major versions without expiry, but existing settings can differ and owners may break inheritance when permitted by the tenant configuration.

Automatic policy can optimize storage, while manual policy can remove versions beyond an age or count. An organization-level change does not necessarily align existing libraries. The presence of a Version history button therefore proves neither minimum retention, uniform coverage nor a copy outside the site's administrative scope.

Inventory exceptions before using versions in an RPO. For critical data, document version count, expiry, who can change settings and the behaviour of non-Office formats or frequently modified files.

04

Recycle bins and employee departure follow different timelines

For SharePoint Online, Microsoft documents 93 days across the site and site-collection recycle bins. A deleted site is also retained for 93 days before its content and settings are permanently deleted. An API or administrative purge can bypass the normal recycle path, so the recovery plan must include automated deletions and the accounts allowed to purge.

A OneDrive follows another timeline after its user is deleted. Its default retention period is 30 days and can be changed in SharePoint administration. At the end of that period, OneDrive moves to the site-collection recycle bin for 93 days. Assign a manager or secondary owner so a poorly handled departure does not turn personal storage into delayed data loss.

These windows are safety nets, not universal retention. Late discovery, purge, a scope error or incomplete offboarding can exceed them. Backup should continue protecting the account after it leaves active scope for an approved period.

05

Why Purview, eDiscovery and backup remain complementary

A Purview policy retains or deletes content according to regulatory and information-lifecycle requirements. It can preserve prior content in the Preservation Hold Library and prevent a user deletion from immediately removing a record. That is essential for compliance, but its purpose, scope and search model are not those of rapid operational recovery.

An eDiscovery case addresses a specific investigation or legal matter. Microsoft recommends retention policies and labels for long-term preservation unrelated to a case. Conversely, Microsoft states that OneDrive or SharePoint data existing only in Microsoft 365 Backup is not discoverable with existing eDiscovery tools. Design both plans together without assuming either replaces the other.

The separation is also technical: Microsoft says retention and deletion policies do not automatically flow through to Microsoft 365 Backup. A compliance deletion of live content therefore does not simultaneously remove backup recovery points. This is the kind of logical independence that a version of the live file does not provide.

06

Start with loss scenarios, not products

A useful strategy starts with the events that must be recovered. For each scenario, record who can cause it, when it might be detected, how much change can be lost and how long operations can wait. A mechanism can be excellent for one deleted file and unsuitable for 800 encrypted sites.

ScenarioUseful native protectionQuestion the backup must answer
File overwritten yesterdayVersion historyDoes the correct version still exist and who can restore it?
Library encrypted 10 days ago30-day library restoreCan a healthy point be identified and has restore been tested?
Deletion found after several monthsRetention if it covered the contentDoes backup extend beyond native windows?
Account deleted during offboardingOneDrive retention and secondary ownerDoes protection continue after removal from active policy?
Malicious administrator or applicationAudit, Conditional Access and rolesDo recovery points have separate administration and a grace period?
Large-scale ransomwareNative detection and restoreHas the RTO for hundreds of sites been measured?
Incorrect Purview policyAudit and delayed enforcementDoes compliance deletion also affect the backup copy?
07

Define RPO, RTO, scope and retention before shopping

RPO is the maximum amount of change the organization accepts losing. RTO is the maximum time before service returns. Set them by class: finance, HR, clinical procedures, project sites, Teams, communication sites and personal OneDrive accounts do not necessarily have the same criticality.

For OneDrive and SharePoint, Microsoft 365 Backup documents a 10-minute RPO for the trailing two weeks and weekly points from 2 to 52 weeks for full restores. Granular file and folder restore provides roughly daily points for the first 14 days, then weekly points. A policy recovery window can be set to 3 months, 6 months, 1 year or 2 years; verify cadence for longer periods when selecting the policy.

Do not confuse RPO with a displayed job frequency. Measure RTO too: declare the incident, obtain rights, find a healthy point, run the restore, validate permissions and return users to work. Microsoft publishes performance expectations, but item count, point type and scope affect the actual result.

Minimum record for each data set
Business owner:
Included sites / OneDrive / Teams:
Classification and legal requirements:
Target RPO:
Target RTO:
Retention period:
Oldest required recovery point:
Granular or full restore:
Restore target: original / alternate URL / export:
Authorized administrators:
Test frequency:
Evidence from last test:
Dependencies: Entra ID, groups, apps, metadata, links:
08

Choose native features, Microsoft 365 Backup or a partner solution

Native features may be sufficient for low-criticality data when their windows are accepted, settings are controlled and restore is tested. Microsoft 365 Backup adds a true protection scope, recovery points, granular or full restore and append-only storage. It is consumption billed and remains in the tenant's Microsoft 365 infrastructure and geography.

Microsoft says its storage is append-only to prevent modification of existing points, but backup deletion is not absolutely blocked. A 90-day grace period after offboarding helps recover backups, and multi-admin notifications reduce malicious-action risk. Include that nuance in the immutability assessment.

A partner product can add multitenant management, another destination, longer retention, export or other workloads. The word 'third party' does not guarantee an independent copy: some products use Microsoft 365 Backup Storage. Ask where data resides, who controls keys and deletion, how bulk restore works and how data is recovered when the contract ends.

OptionGood fitValidate before purchase
Native protections onlyLow criticality, short window, simple restoreActual settings, rapid detection and no regulatory dependency
Microsoft 365 BackupFast integrated recovery at scaleScope, consumption, window, roles, point cadence and geography
Partner on Backup StorageEnhanced experience with Microsoft performancePartner-specific features and the same underlying storage domain
Independent third-party backupRequired administrative or storage separationAPI coverage, fidelity, RTO, export, residency, immutability and exit
09

Inventory the tenant with PowerShell before defining scope

A policy that protects 95 percent of sites can miss the one site required for payroll. Start by inventorying active sites, personal OneDrive accounts, deleted sites and version and offboarding settings. Compare that list with protection units actually covered in Microsoft 365 Backup or the vendor console.

The following script is read-only. It uses Microsoft's SharePoint Online Management Shell and exports results for analysis. Replace the tenant name, run it with an appropriate SharePoint role and protect the reports: URLs, owners and volumes are sensitive administrative data.

Read-only SharePoint and OneDrive inventory
Import-Module Microsoft.Online.SharePoint.PowerShell -ErrorAction Stop

$tenantName = 'contoso'
$adminUrl = "https://$tenantName-admin.sharepoint.com"
$output = Join-Path $PWD ("M365-recovery-inventory-{0}" -f (Get-Date -Format 'yyyyMMdd-HHmm'))
New-Item -ItemType Directory -Path $output -ErrorAction Stop | Out-Null

Connect-SPOService -Url $adminUrl

$activeSites = @(Get-SPOSite -Limit ALL -IncludePersonalSite $true)
if ($activeSites.Count -eq 0) { throw 'No active site returned; validate tenant and permissions.' }

$deletedSites = @(Get-SPODeletedSite -Limit ALL -IncludePersonalSite)
$tenant = Get-SPOTenant

$activeSites | Select-Object Url,Owner,Template,StorageUsageCurrent,LastContentModifiedDate,LockState |
    Export-Csv (Join-Path $output 'active-sites-and-onedrive.csv') -NoTypeInformation -Encoding UTF8

$deletedSites | Select-Object * |
    Export-Csv (Join-Path $output 'deleted-sites-and-onedrive.csv') -NoTypeInformation -Encoding UTF8

$tenant | Select-Object OrphanedPersonalSitesRetentionPeriod,EnableAutoExpirationVersionTrim,ExpireVersionsAfterDays,MajorVersionLimit |
    Export-Csv (Join-Path $output 'tenant-recovery-settings.csv') -NoTypeInformation -Encoding UTF8

[pscustomobject]@{
    CollectedAtUtc = [datetimeoffset]::UtcNow.ToString('o')
    ActiveProtectionUnits = $activeSites.Count
    DeletedProtectionUnits = $deletedSites.Count
    OutputPath = $output
} | Format-List
10

Protect the backup control plane too

A copy is useful only when an attacker cannot neutralize it with the same compromised account. Use the dedicated Microsoft 365 Backup Administrator role instead of Global Administrator where possible, protect it with phishing-resistant authentication and Conditional Access, and monitor role assignments, policy changes, exclusions and restores.

Separate duties: one person defines scope and another approves retention reductions or mass restore. Maintain a controlled emergency account, document access when Entra ID or the portal is unavailable and send alerts to logging that the backup administrator cannot erase alone.

File backup also does not necessarily recreate all tenant configuration. Inventory groups, permissions, labels, applications, Power Automate flows, SharePoint settings and Teams dependencies. Regular configuration exports reduce rebuild time, even though they do not replace content backup.

11

Test restore as a production procedure

A green dashboard does not prove recoverability. Every quarter, select a representative file, folder, OneDrive and site. Restore them to a controlled location and verify content, versions, metadata, permissions, links and elapsed time. For in-place recovery, document what happens to changes created after the selected point.

Run an annual large-scale exercise too: multiple sites, deleted accounts and the primary administrator unavailable. Measure decision time as well as transfer. The procedure should specify evidence, business validation, user communication, rollback and secure closure of temporary restore locations.

  • Confirm every critical protection unit is actually creating recovery points.
  • Test a recent point and the oldest point required by policy.
  • Restore in place and to an alternate URL when both scenarios are planned.
  • Compare measured RTO with approved RTO and correct gaps.
  • Have the business owner validate files, not only the IT team.
  • Document partial failures, missing permissions and unrestored dependencies.
12

The pragmatic conclusion

OneDrive and SharePoint provide excellent resiliency and several ways to correct a recent mistake. Simply using them does not create a complete backup strategy. A strategy exists only when scope, RPO, RTO, retention, administrative separation, loss scenarios and restore tests are defined and proven.

For a small organization, the right answer may be to harden and document native features, then back up only critical sites. For a regulated organization or one heavily dependent on Microsoft 365, full coverage with Microsoft 365 Backup, an independent product or a combination is often more coherent. The product follows the analysis; a tested restore remains the only proof.